Skip to content
Discussion options

You must be logged in to vote

You can add an arbitrary job to the SOC PCAP interface (click the + button). Leave the src or dest port blank if you don't want to limit it to a particular port.

Example:

You can also access large PCAPs from the terminal, but this process has not been documented.

Example:

docker exec -it so-sensoroni scripts/stenoquery.sh "host 192.168.4.15 and host 192.168.4.4 and port 445 and after 2020-06-09T00:00:00Z and before 2020-06-10T00:00:00Z" -w /nsm/pcapout/some.pcap

Replies: 3 comments 4 replies

Comment options

You must be logged in to vote
1 reply
@erik4711
Comment options

Answer selected by defensivedepth
Comment options

You must be logged in to vote
1 reply
@erik4711
Comment options

Comment options

You must be logged in to vote
2 replies
@erik4711
Comment options

@jmdale83
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants